diff options
author | zsdc <taras@vyos.io> | 2023-09-13 12:41:04 +0300 |
---|---|---|
committer | zsdc <taras@vyos.io> | 2023-11-20 18:44:31 +0200 |
commit | 2a023b878471500bd78962ca94d9174a328ce5c9 (patch) | |
tree | 2d3ccd8d77cb6410d943395b72a963f07a0c5e70 /src/pam-configs/radius-optional | |
parent | 9cf2f2c8019b0d0279d6af942a08b6bd829daa16 (diff) | |
download | vyos-1x-2a023b878471500bd78962ca94d9174a328ce5c9.tar.gz vyos-1x-2a023b878471500bd78962ca94d9174a328ce5c9.zip |
RADIUS: T5577: Added `mandatory` and `optional` modes for RADIUS
In CLI we can choose authentication logic:
- `mandatory` - if RADIUS answered with `Access-Reject`, authentication must
be stopped and access denied immediately.
- `optional` (default) - if RADIUS answers with `Access-Reject`,
authentication continues using the next module.
In `mandatory` mode authentication will be stopped only if RADIUS clearly
answered that access should be denied (no user in RADIUS database, wrong
password, etc.). If RADIUS is not available or other errors happen, it will be
skipped and authentication will continue with the next module, like in
`optional` mode.
Diffstat (limited to 'src/pam-configs/radius-optional')
-rw-r--r-- | src/pam-configs/radius-optional | 19 |
1 files changed, 19 insertions, 0 deletions
diff --git a/src/pam-configs/radius-optional b/src/pam-configs/radius-optional new file mode 100644 index 000000000..9f6d5f0ea --- /dev/null +++ b/src/pam-configs/radius-optional @@ -0,0 +1,19 @@ +Name: RADIUS authentication (optional mode) +Default: no +Priority: 576 + +Auth-Type: Primary +Auth-Initial: + [default=ignore success=end] pam_radius_auth.so +Auth: + [default=ignore success=end] pam_radius_auth.so use_first_pass + +Account-Type: Primary +Account: + [default=ignore success=1] pam_succeed_if.so user notingroup radius quiet + [default=ignore new_authtok_reqd=done success=end perm_denied=bad auth_err=bad] pam_radius_auth.so + +Session-Type: Additional +Session: + [default=ignore success=1] pam_succeed_if.so user notingroup radius quiet + [default=ignore success=ok perm_denied=bad auth_err=bad] pam_radius_auth.so |